VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 673 of 727
  • CVE-2025-43501MedDec 17, 2025
    risk 0.28cvss 4.3epss 0.01

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2025-58480MedDec 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-58478MedDec 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-58477MedDec 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2024-11920MedNov 14, 2025
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-64406MedNov 12, 2025
    risk 0.28cvss 4.3epss 0.01

    An out-of-bounds Write vulnerability in Apache OpenOffice could allow an attacker to craft a document that would crash the program, or otherwise corrupt other memory areas. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrade to version…

  • CVE-2025-21075MedNov 5, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-43421MedNov 4, 2025
    risk 0.28cvss 4.3epss 0.01

    Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2025-3203MedApr 4, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in Tenda W18E 16.01.0.11. Affected by this vulnerability is the function formSetAccountList of the file /goform/setModules. The manipulation of the argument Password leads to stack-based buffer overflow. The attack can be…

  • CVE-2025-0143MedJan 30, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds write in the Zoom Workplace App for Linux before version 6.2.5 may allow an unauthorized user to conduct a denial of service via network access.

  • CVE-2020-9086MedDec 27, 2024
    risk 0.28cvss 4.3epss 0.00

    There is a buffer error vulnerability in some Huawei product. An unauthenticated attacker may send special UPNP message to the affected products. Due to insufficient input validation of some value, successful exploit may cause some service abnormal. (Vulnerability ID:…

  • CVE-2024-12352MedDec 9, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function sub_40662C of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be…

  • CVE-2024-44244MedOct 28, 2024
    risk 0.28cvss 4.3epss 0.01

    A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2024-40723MedAug 2, 2024
    risk 0.28cvss 4.3epss 0.00

    The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the length of server-side inputs. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the…

  • CVE-2024-40722MedAug 2, 2024
    risk 0.28cvss 4.3epss 0.00

    The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate the length of server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the…

  • CVE-2024-32672MedMay 14, 2024
    risk 0.28cvss 5.3epss 0.01

    A Segmentation Fault issue discovered in Samsung Open Source Escargot JavaScript engine allows remote attackers to cause a denial of service via crafted input. This issue affects Escargot: 4.0.0.

  • CVE-2024-32669MedMay 14, 2024
    risk 0.28cvss 5.3epss 0.01

    Improper Input Validation vulnerability in Samsung Open Source escargot JavaScript engine allows Overflow Buffers. However, it occurs in the test code and does not include in the release. This issue affects escargot: 4.0.0.

  • CVE-2024-30613MedMar 29, 2024
    risk 0.28cvss 4.3epss 0.00

    Tenda AC15 v15.03.05.18 has a stack overflow vulnerability in the time parameter from the setSmartPowerManagement function.

  • CVE-2024-29133MedMar 21, 2024
    risk 0.28cvss 5.4epss 0.02

    Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.

  • CVE-2023-51074MedDec 27, 2023
    risk 0.28cvss 5.3epss 0.01

    json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.